Extended Key Usage

Extended Key Usage (EKU) is a method of enforcing the public key of a certificate to be used for a pre-determined set of key purposes.

There can be one or more such key purposes defined. This extension is usually defined by the end entity systems in their certificates to support their security design constraints. When EKU is present in a certificate, it implies that the public key can be used in addition to or in place of the basic purposes listed in the key usage extension. The EKU extension is always tagged as critical.

The feature enables PKI clients like TLS or IKE to include EKU extension in their certificates and also process received EKU enabled certificates from peer and take action (accept or reject a connection). The EKU extension has key purposes as follows:

  • Server authentication (OID 1.3.6.1.5.5.7.3.1)
  • Client Authentication (OID 1.3.6.1.5.5.7.3.2)
  • anyExtendedKeyUsage (OID 2.5.29.37.0)

Every fields are uniquely identified by an OID.

System in FIPS Mode

Upon receiving a peer certificate:

  • For an IKE client, if peer certificate contains an EKU without "anyExtendedKeyUsage" set, the certificate is rejected. If the peer certificate does not contain the EKU extension, the certificate is accepted.
  • For a TLS client, if peer certificate does not have an EKU extension, or contains an EKU without server authentication set, the certificate is rejected.

System in Non-FIPS Mode

Upon receiving a peer certificate:

  • For an IKE client, if peer certificate contains an EKU without "anyExtendedKeyUsage" set, the certificate is rejected. If the peer certificate does not contain the EKU extension, the certificate is accepted.
  • For a TLS client, if peer certificate does not have an EKU extension, the certificate is accepted. If the EKU extension is available without server authentication set, the certificate is rejected.

Configuration

The EKU extension is not enabled by default in the certificate. The PKI client (like IKE/TLS) has to provision it explicitly using the extended-key-usage command.

device(config)#pki trustpoint <trust-point name>
device(config-pki-trustpoint-trust1)#extended-key-usage ?
client-auth			Enable client authentication.
server-auth			Enable server authentication.
any				Enable any extended key

The NO form of this command disables the EKU extension.